- Multiple security fixes address CVE‑2026‑26330, 26308, 26310, 26309 and 26311 (rate‑limit crash, RBAC header bypass, IPv6 address handling, JSON off‑by‑one write, HTTP decode after reset).
- Bug fixes include OAuth2 host‑rewrite handling, ext‑proc chain support and CEL attribute serialization, proper propagation of denied‑authz headers, error‑status handling for ext authz, and a crash on listener removal with access‑log rate...
- Introduces an extended ABI forward‑compatibility mechanism for dynamic modules, updates contrib binary version strings, and refreshes dependencies such as googleurl, Kafka test binary and Docker base images.